Google Doc Embedder [google-document-embedder] <= 2.6.4 (unfixed + closed)
unknown
[en] The Google Doc Embedder plugin for WordPress is vulnerable to Server Side Request Forgery via the 'gview' shortcode in versions up to, and including, 2.6.4. This can allow authenticated attackers with contributor-level permissions or above to make web requests to arbitrary locations originating from the web applic...
- Affected:
- up to 2.6.4
- Fix:
- No patched version reported
- Disclosed:
- Apr 30, 2024
CVE-2024-0216 on NVD →
Google Doc Embedder <= 2.6.4 - Authenticated (Contributor+) Blind Server Side Request Forgery
medium
The Google Doc Embedder plugin for WordPress is vulnerable to Server Side Request Forgery via the 'gview' shortcode in versions up to, and including, 2.6.4. This can allow authenticated attackers with contributor-level permissions or above to make web requests to arbitrary locations originating from the web application...
- CVSS:
- 6.4
- Affected:
- up to 2.6.4
- Fix:
- No patched version reported
- Disclosed:
- Apr 29, 2024
CVE-2024-0216 on NVD →
Google Doc Embedder [google-document-embedder] < 2.6.2 (closed)
unknown
[en] The google-document-embedder plugin before 2.6.2 for WordPress has CSRF.
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.2
- Disclosed:
- Aug 14, 2019
CVE-2016-10882 on NVD →
Google Doc Embedder [google-document-embedder] < 2.6.2 (closed)
unknown
[en] The google-document-embedder plugin before 2.6.2 for WordPress has XSS.
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.2
- Disclosed:
- Aug 14, 2019
CVE-2016-10881 on NVD →
Google Doc Embedder [google-document-embedder] < 2.6.1 (closed)
unknown
[en] The google-document-embedder plugin before 2.6.1 for WordPress has XSS.
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
- Disclosed:
- Aug 14, 2019
CVE-2016-10880 on NVD →
Google Doc Embedder <= 2.6.1 - Cross-Site Request Forgery
high
The Google Doc Embedder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.1. This makes it possible for unauthenticated attackers to conduct attacks such as cross-site scripting via forged request granted they can trick a site administrator into performing an action...
- CVSS:
- 8.8
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.2
- Disclosed:
- Sep 27, 2016
CVE-2016-10882 on NVD →
Google Doc Embedder <= 2.6.1 - Cross-Site Scripting
medium
The google-document-embedder plugin before 2.6.2 for WordPress has XSS.
- CVSS:
- 6.1
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.2
- Disclosed:
- Sep 27, 2016
CVE-2016-10881 on NVD →
Google Doc Embedder <= 2.6 - Cross-Site Scripting
medium
The google-document-embedder plugin before 2.6.1 for WordPress has XSS.
- CVSS:
- 6.1
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
- Disclosed:
- Sep 22, 2016
CVE-2016-10880 on NVD →
Google Doc Embedder < 2.5.17 - SQL Injection
critical
SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL commands via the gpid parameter.
- CVSS:
- 9.8
- Affected:
- up to 2.5.17
- Fixed in:
- 2.5.17
- Disclosed:
- Nov 28, 2015
CVE-2014-9173 on NVD →
Google Doc Embedder [google-document-embedder] < 2.5.19 (closed)
unknown
[en] Cross-site scripting (XSS) vulnerability in the Google Doc Embedder plugin before 2.5.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the profile parameter in an edit action in the gde-settings page to wp-admin/options-general.php.
- Affected:
- up to 2.5.19
- Fixed in:
- 2.5.19
- Disclosed:
- Feb 19, 2015
CVE-2015-1879 on NVD →
Google Doc Embedder <= 2.5.18 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the Google Doc Embedder plugin before 2.5.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the profile parameter in an edit action in the gde-settings page to wp-admin/options-general.php.
- CVSS:
- 5.4
- Affected:
- up to 2.5.19
- Fixed in:
- 2.5.19
- Disclosed:
- Jan 26, 2015
CVE-2015-1879 on NVD →
Google Doc Embedder [google-document-embedder] < 2.5.17 (closed)
unknown
[en] SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL commands via the gpid parameter.
- Affected:
- up to 2.5.17
- Fixed in:
- 2.5.17
- Disclosed:
- Dec 2, 2014
CVE-2014-9173 on NVD →
Google Doc Embedder [google-document-embedder] < 2.5.15 (closed)
unknown
This WordPress Google Document Embedder plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Update to version 2.5.15.
- Affected:
- up to 2.5.15
- Fixed in:
- 2.5.15
- Disclosed:
- Nov 25, 2014
Google Doc Embedder [google-document-embedder] < 2.5.4 (closed)
unknown
[en] Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to libs/pdf.php.
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.4
- Disclosed:
- May 29, 2014
CVE-2012-4915 on NVD →
Google Doc Embedder < 2.5.4 - Directory Traversal
high
Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to libs/pdf.php.
- CVSS:
- 7.5
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.4
- Disclosed:
- Jan 8, 2013
CVE-2012-4915 on NVD →
Google Doc Embedder [google-document-embedder] < 2.4.7 (closed)
unknown
Google Document Embedder plugin is prone to an arbitrary file disclosure vulnerability. It allows for database credential disclosure via the /libs/pdf.php script.
Update the plugin.
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.7
- Disclosed:
- Jan 8, 2013
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database